On 13/12/17 11:58, Tim Shirley wrote: > So many of the arguments made here, such as this one, as well as the recent > demonstrations that helped start this thread, focus on edge cases. And while > those are certainly valuable to consider, they obscure the fact that “Green > Bar” adds value in the mainstream use cases. If we were talking about how to > improve EV, then by all means focus on the edge cases. The thing I don’t see > in all this is a compelling argument to take away something that’s useful > most of the time.
My concern with this argument is that it's susceptible to the criticism that Adam Langley made of revocation checking: https://www.imperialviolet.org/2012/02/05/crlsets.html "So [EV identity is] like a seat-belt that snaps when you crash. Even though it works 99% of the time, it's worthless because it only works when you don't need it." Gerv _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

